GDPR Privacy
This summary provides a quick overview before diving into the full GDPR guide below.
GDPR Quick Summary
- What is GDPR? A European privacy law enforced on May 25, 2018, designed to protect the personal data of EU and EEA residents.
- Who it applies to: Any organization that processes or stores personal data of EU/EEA citizens, regardless of where the organization is located.
- Personal data includes: Names, emails, photos, social media activity, and IP addresses — any information that can identify an individual.
- Consent: Must be explicit and recorded for marketing emails, competitions, and non-essential data processing.
- Rights of individuals: Access, erasure, portability, correction, restriction, objection, and notification of data breaches.
- Steps to compliance:
- Conduct a full data audit
- Run a consent review or re-permissioning campaign
- Ensure a clear, accessible privacy policy
- Set up procedures for data requests and breach handling
- Follow guidance from your data protection authority (e.g. ICO)
- Fines: Up to €20 million or 4% of global annual turnover for serious non-compliance.
What is GDPR Privacy?
Perhaps you’ve noticed the influx of GDPR privacy emails in May 2018 – these were from companies requesting permission to keep you on their subscriber lists.
Although GDPR had been in development for many years, it officially came into force on May 25th, 2018.
GDPR, the General Data Protection Regulation, is a European privacy law that harmonizes data protection across all EU and EEA countries. It applies to any organization that processes the personal data of EU/EEA residents, regardless of where the organization itself is located.
This legislation empowers individuals to have more control over their personal data while setting clear responsibilities for organizations on how they collect, store, and use that data.
Personal data can include anything that identifies a person, such as names, email addresses, photos, social media updates, or even an IP address. GDPR applies to both personal and professional contexts, though certain exemptions may apply for employment-related data processing.
In short: if you collect, store, or process personal data of EU/EEA residents, GDPR applies to you.
What does GDPR privacy mean for you?
Don’t panic. While GDPR enforcement can result in fines of up to €20 million or 4% of global annual turnover, authorities generally issue warnings and corrective measures first.
GDPR ensures organizations handle personal data responsibly. If your current practices already respect privacy, you are likely on the right track. This is an opportunity to improve your data management processes.
For example, email marketing now requires explicit consent. You cannot send marketing emails to individuals unless they have specifically opted in. The same rules apply to competitions or mailing lists: individuals must know how their data will be used, and you must record their consent.
Existing customers may still be contacted under a legitimate interest, but you must allow them to opt out and respect any withdrawal of consent.
The key is keeping data accurate, up-to-date, and only processing it with a lawful basis such as consent, contract, or legitimate interest.
Steps to becoming GDPR-compliant
1. Conduct a data audit
Identify the types of personal data you store, how you use it, where it is stored, and who has access. Review your security practices and ensure that data is only collected and kept where necessary.
2. Manage consent
Ensure that you have GDPR-compliant consent records for individuals, including email subscribers. If prior consent is unclear or not compliant, consider a re-permissioning campaign to obtain valid consent.
3. Ensure compliance with data subject rights
Individuals have specific rights under GDPR. Your processes should support these rights:
- Right of access
- Right to be forgotten (erasure)
- Right to data portability
- Right to be informed
- Right to have information corrected
- Right to restrict processing
- Right to object
- Right to be notified of breaches
4. Draft a GDPR privacy policy
Display a clear privacy policy for anyone submitting personal data – whether signing up for emails, registering for services, or other purposes. A checklist can help you ensure nothing is missed. View GDPR privacy policy checklist
5. Plan how to handle data requests
Individuals may request updates, deletion, or copies of their data. Implement procedures to respond within the legal timescale, typically one month.
6. Plan for data breaches
Despite precautions, breaches can occur. Have a clear plan to detect, report, and investigate any data breaches, in compliance with GDPR.
7. Identify your lead data protection authority
If operating in multiple EU member states, determine which authority is your lead supervisory authority. Guidance from the Article 29 Working Party is very helpful.
8. Consult GDPR guidance
Reliable sources, such as the UK Information Commissioner’s Office (ICO), provide detailed guidance and best practices.
Key GDPR privacy resources to keep bookmarked
- ICO (UK): Preparing for GDPR – ’12 Steps to Take Now’
- Full GDPR text: Regulation
- European Commission GDPR resources
- DMA UK GDPR updates
In Summary
If you’re not fully GDPR-compliant yet, use this as an opportunity to improve your data handling practices. Follow the steps outlined above and ensure your privacy policy is clear and up-to-date.




